SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

31 results for “kev-cve-2025-26633” · 1.01 s · cached

Facets · 1 entity types

31 CVE
CVE-2026-43331CVE

CVE-2026-43331

In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Disable KCOV instrumentation after load_segments() The load_segments() function changes segment registers, invalidatin…

CVSS 5.5EPSS 0.1%linux
Match for kev-cve-2025-26633
CVE-2026-34612CVE

CVE-2026-34612

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Exec…

CVSS 9.9EPSS 0.7%kestra
Match for kev-cve-2025-26633
CVE-2025-26647CVE

CVE-2025-26647

Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

CVSS 8.8EPSS 2.2%
Match for kev-cve-2025-26633
CVE-2025-46633CVE

CVE-2025-46633

Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the sym…

CVSS 8.2EPSS 0.3%
Match for kev-cve-2025-26633
CVE-2026-5433CVE

CVE-2026-5433

Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could exploit this vulnerability via command delimiters, potentially resulting in Rem…

CVSS 9.1EPSS 1.6%
Match for kev-cve-2025-26633
CVE-2026-48556CVE

CVE-2026-48556

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-26633
CVE-2025-40263CVE

CVE-2025-40263

In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`…

EPSS 0.2%
Match for kev-cve-2025-26633
CVE-2026-46269CVE

CVE-2026-46269

In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree When probing the k230 pinctrl driver, the kernel trig…

CVSS 5.5EPSS 0.2%linux
Match for kev-cve-2025-26633
CVE-2024-56123CVE

CVE-2024-56123

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-26633
CVE-2026-46263CVE

CVE-2026-46263

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder index v3 eng_id can be negative and that stream_enc_regs[] can be indexed out o…

CVSS 7.8EPSS 0.2%linux
Match for kev-cve-2025-26633
CVE-2024-56122CVE

CVE-2024-56122

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Match for kev-cve-2025-26633
CVE-2026-31553CVE

CVE-2026-31553

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva + offset" to get the virtual addresses of…

CVSS 8.8EPSS 0.2%
Match for kev-cve-2025-26633
CVE-2026-26722CVE

CVE-2026-26722

An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to escalate privileges via PIN component of the login functionality.

CVSS 9.4EPSS 0.5%
Match for kev-cve-2025-26633
CVE-2026-32193CVE

CVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

CVSS 8.8EPSS 0.4%microsoft
Match for kev-cve-2025-26633
CVE-2026-38428CVE

CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitiza…

CVSS 9.8EPSS 0.5%kestra
Match for kev-cve-2025-26633
CVE-2026-26723CVE

CVE-2026-26723

Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter.

CVSS 8.2EPSS 0.5%
Match for kev-cve-2025-26633
CVE-2026-45653CVE

CVE-2026-45653

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVSS 7.0EPSS 0.3%microsoft
Match for kev-cve-2025-26633
CVE-2026-46612CVE

CVE-2026-46612

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission storagesvc component…

CVSS 8.8EPSS 0.7%
Match for kev-cve-2025-26633
CVE-2025-26597CVE

CVE-2025-26597

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same f…

CVSS 7.8EPSS 0.4%tigervnc
Match for kev-cve-2025-26633
CVE-2026-35433CVE

CVE-2026-35433

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

CVSS 7.3EPSS 0.6%microsoft
Match for kev-cve-2025-26633
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.